-
-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Labels
area:securitySafety gates and security validationSafety gates and security validationphase:1Self-Incorporation Phase 1 - Core InfrastructureSelf-Incorporation Phase 1 - Core Infrastructuretype:featureNew feature implementationNew feature implementation
Milestone
Description
Strict mode gates (signatures + caps)
Labels: phase:1, area:security, type:feature
Milestone: Self-Incorporation v1
Description
Enable strict mode which enforces .aether HMAC signatures, plugin ed25519 signatures,
and deny-by-default capability policy.
Acceptance Criteria
- When
AETHERRA_SELFINC_STRICT=1:- .aether HMAC signature verification must pass, else quarantine
- Plugin artifacts must verify ed25519 signature, else quarantine
- Deny-by-default capability policy; require explicit allowlist
- Quarantine includes remediation guidance in logs/messages
- Unit tests for positive path and quarantine path
Metadata
Metadata
Assignees
Labels
area:securitySafety gates and security validationSafety gates and security validationphase:1Self-Incorporation Phase 1 - Core InfrastructureSelf-Incorporation Phase 1 - Core Infrastructuretype:featureNew feature implementationNew feature implementation